A browser is not a VPN. Session-only cookies and cache do not hide your IP address from sites you visit or from your network operator. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.
A no-history browser still needs cookies. That sentence surprises people who wanted the word private to mean the page runs in a vacuum. The web does not work in a vacuum. A login has to stick for the tab you are using. A cart has to remember a size. A script should not download on every scroll. Cookies and cache are how that happens. In Private Browser Incognito they live only for the session. They are tools, not a diary.
The diary is the history file, and this app does not write one. Mixing the two stores is how a FAQ turns into a contradiction: either the browser is broken because you got signed out, or it is not private because a cookie existed. Both complaints miss the scope. Session storage is for the visit. History is a log of visits. Erase ends the first. The second was never created.
What cookies are doing in a tab
When a site sets a cookie, it is asking the browser to send a small token back on later requests to that site. That is how you stay signed in as you click from page to page. It is how a language banner stays dismissed. It is also how some trackers try to recognize a browser across pages. The mechanism is the same. The difference is lifetime and whether extra third-party requests are allowed to fire.
In a forgetful browser, cookies exist for the life of the session. They are not promoted into a long-lived jar you are expected to inspect under Settings. You do not get a history-like list of every cookie name. You get a working tab, then a wipe. If you need the visit not to attach to an account, do not sign in. Erase will still destroy whatever session tokens were set. It will not rewind the requests that already went out under that account. That limit belongs with What Incognito Mode Does Not Hide.
Third-party cookies and tracker pixels are a separate layer. On-device lists, powered by the open Disconnect lists that ship in the app, block known ads, analytics, and social trackers. Blocking is not complete. New names appear. Per-site exceptions exist when a page needs a blocked resource to function. Session lifetime and list-based blocking work together. Neither one is a cloak.
What cache is for
Cache holds images, scripts, and other assets so the next scroll does not refetch everything. It is a performance store, not a reading list. In a general browser, cache can outlive a tab for days. In a forgetful browser, cache is session-scoped along with cookies and site data. It is there while you are using the pages. It is not meant to be an archaeological layer after you leave.
Site data is the broader bucket: cookies, cache, and other storage a page may use while it is open. One-tap erase destroys that bucket when it closes every tab. There is no separate cookie pane you are expected to mop up later. That is the point of session-only design. If a comparison chart lists “clear cookies” as a weekly chore, it is describing a different architecture.
Memory sessions are described in A Browser With No History File at All. Cookies and cache are the part of memory that makes the page function. History would have been the part that makes the page findable next week. Only the first part ships.
Closing a tab is not erase
Dismissing a page removes that page from the screen. Other tabs can still be alive, and they may still need cookies. App Lock with a six-digit passcode and Face ID can hide the remaining session from someone who picks up the phone. Lock does not delete cookies. Erase does.
One-tap erase closes every tab and destroys cookies, cache, and site data. There is a home-screen quick action so you can wipe without opening the UI first. Erased data cannot be recovered, by you or by us. The full control map, including what the vault does, is in Erase Everything in One Tap.
Stealth Suite adds an Auto-Erase timer if you want the session to die after you leave the app. That timer is still session destroy. It is not a vault wipe. Panic code can wipe tabs, the vault, and the break-in log together. Do not use panic because you wanted cookies gone and files kept.
What session-only does not do
Session cookies do not hide your IP. The site that set them still sees the connection. Your network operator still sees destinations. HTTPS-Only Mode, on by default, encrypts the path when the site supports it and asks before falling back to HTTP. Encryption is not a new identity.
Search is not a cookie problem. A query you send to Google, Bing, DuckDuckGo, Wikipedia, or a custom engine is a request that engine can log. Suggestions stay off by default. The app asks before sharing a keystroke. The private browser does not keep a local history of the search. The engine still received it.
There are no accounts in the app and no browsing server. The App Store privacy label is Data Not Collected. We do not hold a copy of your cookie jar. Sites you visit still do, for as long as their own servers remember the session you opened. Local lifetime is the only lifetime we control.
Per-site permissions are also session-adjacent, not a cookie store. Camera and microphone are asked for when a website requests them. That is the page talking to the OS, not a tracker we invent. HTTPS-Only Mode, already mentioned, is a transport default. It does not decide whether a cookie may exist. It decides whether the conversation that carries the cookie is allowed to fall back to plain HTTP without asking you.
If you came here from a comparison that treats any cookie as a leak, apply a narrower test. Did the engine write a history file? After erase, do cookies and cache remain? Those two answers define a forgetful browser. A live cookie on an open tab is how the site you chose keeps its own state. That is expected, documented, and temporary.
A compact map of the stores
| Store | While the session is open | After erase |
|---|---|---|
| History file | Does not exist | Still does not exist |
| Cookies | Session-scoped, so the tab can work | Destroyed |
| Cache and site data | Session-scoped | Destroyed |
| Encrypted vault | Separate store, if you use Stealth Suite | Left intact |
Use that map when a review says a private browser “still uses cookies” as if that were a gotcha. Of course it does, if it is a real web browser, rated 17+ for unrestricted access. The honest claim is lifetime: cookies and cache that live only for the session, a history file that never appears, and an erase button that actually destroys the stores the page needed. That is enough for a borrowed phone. It is not a VPN, and it is not a site that forgot you while you were still logged in.
Frequently asked questions
Do cookies work in a private browser on iPhone?
Yes. Sites can set cookies so a login, a cart, or a language preference sticks for that visit. In Private Browser Incognito those stores are session-scoped. They are there so the tab can work. They are not saved into a long-lived history database. One-tap erase destroys them with the rest of the session.
Does cache survive after I close a private browser?
Cache holds images and scripts so a page does not refetch everything on the next scroll. In a forgetful browser it lives for the session. Closing a single tab is not the same as erase. One-tap erase closes every tab and destroys cookies, cache, and site data. There is no separate cookie pane you are expected to mop up later.
If cookies exist, is a no-history browser still private?
Cookies are not a history file. A history file is a diary of URLs. Session cookies are how a site keeps you signed in on the tab you are using. Private means the diary is never written, and erase can destroy the session stores. It does not mean the site you are logged into forgot who you are.
Does erase delete cookies and cache?
Yes. One-tap erase closes every tab and destroys the session: cookies, cache, and site data. Erased data cannot be recovered. Session erase does not clear the encrypted download vault if you use Stealth Suite. The vault is a separate store. Cookies are session tools, not vault files.
Can websites still track me with session cookies?
A site you are using can still set cookies while the tab is open, and it can still see your IP address. On-device lists block known ads, analytics, and social trackers, but blocking is not absolute. Session-only storage limits how long those cookies last on the phone. It does not cloak the live visit.